Privacy Policy

Last updated: July 14, 2026

1. Introduction

Nikali Ltd. ("Company", "we", "us", or "our") operates the NudgePort platform ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service.

We are committed to protecting privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. GDPR Roles (Controller / Processor)

NudgePort's role depends on the type of data:

2.1 NudgePort as Data Controller (platform users)

NudgePort acts as a Data Controller for personal data related to platform users (agencies, freelancers, and their authorized team members), such as account creation, authentication, billing, security, and support.

2.2 NudgePort as Data Processor (client and project data)

For project data, client contact data, and approval records uploaded or entered by NudgePort customers, the customer is the Data Controller and NudgePort acts as a Data Processor on the customer's behalf. NudgePort processes this data only to provide the Service and according to the customer's instructions, under a Data Processing Agreement ("DPA") available in the dashboard and at nudgeport.com/dpa.

3. Information We Collect

3.1 Agency / Account Information

When you register for NudgePort, we may collect:

  • Account and contact details (e.g., name, company or agency name, email address);
  • Country of operation and billing address;
  • Security-related data (e.g., login history, device/session signals, two-step verification status);
  • Billing details needed to provide the Service (e.g., subscription status, invoices, payment identifiers from our payment provider);
  • Consent records (e.g., which terms and policies you agreed to at registration, the exact consent text, policy version, timestamp, IP address, and user agent — stored as an immutable audit trail);
  • Marketing preferences (opt-in/opt-out status for product updates and marketing communications).

3.2 Project, Client & Approval Data (processed for agencies)

When an agency uses NudgePort to manage approvals with its clients, we process project and client information on the agency's behalf. Depending on the agency's configuration and the client's participation, this may include:

  • Client and project contact names and email addresses;
  • Project names, phases, item titles, version labels, and external URLs;
  • Comments, feedback, change requests, approval decisions (approved, rejected, changes requested), timestamps, and activity history;
  • Technical metadata used for security and evidencing (e.g., IP address, user agent);
  • Email delivery-related status for transactional notifications (e.g., accepted/bounced), where available.

Legal Basis for Processing (client and project data): The agency (as Data Controller) determines the legal basis for processing its client data. In many cases, this is related to performing the agency-client contract and legitimate interests in documenting communications and resolving disputes. NudgePort processes this data as a Data Processor solely to deliver the Service (e.g., render the approval portal, send notifications, and maintain the approval workflow). NudgePort does not determine the legal basis for agency client data; we process it only on the agency's instructions to provide the Service.

3.3 Technical Data

We may automatically collect technical and usage information necessary to operate and secure the Service, such as:

  • Log files and service usage data;
  • Device and browser information;
  • IP address;
  • Performance/diagnostic signals.

4. How We Use Your Information

We use information to:

  • Provide and maintain the Service;
  • Authenticate users and secure accounts (including two-step verification and abuse prevention);
  • Send service communications (e.g., account notices, security alerts, transactional emails);
  • Provide customer support and respond to inquiries;
  • Process subscriptions and billing administration;
  • Improve reliability, performance, and user experience;
  • Detect, prevent, and investigate fraud, abuse, or security incidents;
  • Maintain auditability of administrative actions within the platform;
  • Send product updates and marketing communications (only where you have opted in; you may withdraw consent at any time).

5. Data Retention & Deletion

This section describes what data we retain, for how long, what happens when it is no longer needed, and how you can request deletion or restriction of processing.

5.1 Project and approval records (agency client data)

Project and approval records are retained according to the agency's subscription plan to satisfy contract evidencing and applicable record-keeping requirements:

PlanRetention periodRationale
FreeUp to 1 yearLimited retention for evaluation and trial use
Single ProjectUp to 5 yearsGeneral commercial limitation period in most EU member states
StudioUp to 7 yearsExtended evidencing for ongoing client work
AgencyUp to 10 yearsExtended evidencing for commercial, tax, and contractual obligations

After the retention period expires, records are automatically purged or anonymized. Retention may be extended where required by applicable law or to establish, exercise, or defend legal claims.

5.2 What data is retained in each record

  • Personal identifiers: Client and contact names, email addresses, IP address, user agent — retained for the full retention period unless anonymized earlier upon request.
  • Project and approval data: Project names, phase and item titles, version labels, external URLs, comments, feedback, change requests, approval decisions, and timestamps — retained for the full retention period.
  • Email delivery metadata: Message IDs, delivery status, bounce information — retained for the full retention period to evidence notification delivery.
  • Integrity data: Activity logs and audit references — retained as non-personal or pseudonymized audit evidence where applicable.

5.3 Account and service data (platform users)

We retain account-related data for as long as your account is active and as necessary to provide the Service. Upon account deletion:

  • Account profile data is deleted or anonymized within 30 days;
  • Login history and security event logs are purged within 30 days;
  • Billing records (invoices, payment identifiers) may be retained for up to 10 years as required by Bulgarian accounting and tax law;
  • Admin audit logs referencing the account may be retained for compliance and security purposes.

5.4 Security and operational data

  • Login attempts / brute-force records: Retained for up to 90 days, then automatically purged.
  • Portal verification codes: Expired codes are purged automatically via scheduled cleanup (within 24 hours of expiry).
  • Contact form rate-limit records: Retained for up to 1 hour to enforce per-IP limits, then automatically purged.
  • Health monitoring samples: Retained for up to 14 days for operational diagnostics, then automatically purged.

5.5 Anonymization (Right to be Forgotten)

In lieu of hard deletion, we support irreversible anonymization of personal data in project and approval records. When an anonymization request is approved:

  • Personal identifiers (names, emails, IP addresses, user agents, message IDs) are replaced with "ANONYMIZED" or set to null;
  • Project references are partially retained (e.g., first characters only) for cross-referencing where necessary;
  • Non-identifying metadata (timestamps, integrity hashes, sequence numbers) is preserved to maintain audit trail integrity;
  • The record is flagged with an anonymization marker and timestamp.

Anonymization is irreversible — once processed, the original personal data cannot be recovered.

5.6 How to request deletion or restriction

For platform account data (you are the data subject): Submit a GDPR request by emailing support@nudgeport.com with the subject line "Data Deletion Request". We will process your request within 30 days.

For project and client data (the agency's client is the data subject): Because the agency is the Data Controller, the client should contact the agency directly. The agency can then submit an erasure request through the NudgePort dashboard or by contacting us. Requests are reviewed and processed by our team, typically within 10 business days.

For restriction of processing: You may request that we restrict (rather than delete) processing of your data. During restriction, data is stored but not actively processed. Contact support@nudgeport.com to exercise this right.

5.7 Data retained after deletion for legal reasons

Even after a deletion or anonymization request is fulfilled, certain data may be retained where required by law or legitimate interest:

  • Tax/accounting records: Invoices and billing data retained for up to 10 years (Bulgarian Commercial Act, VAT Act);
  • Legal claims: Data necessary to establish, exercise, or defend legal claims may be retained until the relevant limitation period expires;
  • Security/fraud: IP block records, abuse logs, and security incident data may be retained for ongoing platform protection;
  • Anonymized data: Fully anonymized data (where no individual can be identified) falls outside the scope of GDPR and may be retained indefinitely for statistical and integrity purposes.

6. Data Sharing

We may share information with:

  • Service Providers (Processors): vendors that help us operate the Service (e.g., hosting, email delivery infrastructure for transactional emails, monitoring, and payment processing providers);
  • Legal Requirements: when required by law, court order, or a valid government request;
  • Business Transfers: in connection with a merger, acquisition, or sale of assets (with appropriate safeguards).

We do not sell your personal data to third parties.

7. Your Rights Under GDPR

Depending on your role and the context of processing, you may have rights under GDPR, including:

  • Access: request a copy of your personal data;
  • Rectification: request correction of inaccurate data;
  • Erasure: request deletion of your data (subject to legal and legitimate retention needs);
  • Restriction: request limitation of processing;
  • Portability: receive your data in a structured, machine-readable format;
  • Objection: object to processing based on legitimate interests;
  • Withdraw Consent: where processing is based on consent.

How to exercise your rights

To exercise these rights regarding your platform account data, contact us at support@nudgeport.com.

For project and client data (agency client data): Because the agency is the Data Controller for this data, requests relating to an agency's client data may be directed to the agency first. We will support agencies in fulfilling valid requests in our role as Data Processor where applicable.

8. Data Security

We implement appropriate technical and organizational measures to protect information, including:

  • Encryption in transit and at rest;
  • Access controls and authentication, including role-based permissions;
  • Tenant isolation using database-level Row Level Security (RLS) so that agencies access only their own data;
  • Hashed portal link tokens and one-time email verification codes for secure, passwordless client portal access;
  • Monitoring and abuse prevention measures;
  • Security reviews and operational safeguards;
  • EU-based infrastructure where possible for core data storage and processing.

No system is 100% secure, but we work continuously to protect the Service and the data it processes.

8.1 Bot Protection (IP Rate Limiting)

To protect the Service and prevent automated abuse (e.g., spam through the public contact form), we enforce IP-based rate limiting on certain public endpoints. When a request is received, we temporarily process the IP address to count requests within a rolling time window.

  • Purpose: security and abuse prevention.
  • Legal basis: legitimate interests (service security and abuse prevention).
  • Recipients: NudgePort's hosting and database infrastructure only.

We do not use this mechanism for advertising or tracking. Excess requests are silently blocked without sending emails or creating accounts.

9. Use of Artificial Intelligence

9.1 No AI in Core Service

The core NudgePort approval workflow — including project creation, phase management, item approvals, feedback, notifications, and the client portal — does not use AI or automated decision-making. These features operate using deterministic, rule-based logic only.

9.2 Support and Operational Tools

We may use AI-powered tools in a limited capacity for internal operational or support purposes (for example, drafting documentation or assisting with support responses). Where such tools process personal data, we ensure that processing is limited to what is necessary, does not involve client project data or end-client personal data, and does not produce legal or similarly significant effects.

10. International Transfers

Data is primarily stored and processed within the European Union. If we transfer data outside the EU/EEA, we use appropriate safeguards (such as Standard Contractual Clauses) to protect personal data.

11. Cookies

NudgePort's client portal does not rely on tracking cookies. We use essential cookies or similar technologies required for core functionality and security (for example, maintaining an authenticated session).

If we introduce optional analytics cookies in the future, we will provide a consent mechanism where required by law.

12. Changes to This Policy

We may update this Privacy Policy periodically. We will post the updated version on our website and may notify you of material changes via email or through the Service. Continued use of the Service after changes become effective indicates acceptance of the updated policy.

13. Supervisory Authority

If you believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

As Nikali Ltd. is established in Bulgaria, our lead supervisory authority is the Commission for Personal Data Protection (CPDP), located at 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria. You can reach them via their website at www.cpdp.bg or by email at kzld@cpdp.bg.

14. Contact Us

For questions about this Privacy Policy or to exercise your data rights, contact:

Nikali Ltd. (operating as NudgePort)
Registration Number (UIC): 207724645
VAT Number: BG207724645
Address: 8 Belite Borove St., Gorna Banya, Sofia, Bulgaria
Email: support@nudgeport.com
Website: nudgeport.com

15. Controlling Language

This Privacy Policy is provided in English. The English version is the controlling version. Any translations are for convenience only and have no legal effect.